Skip to content

chore(deps): bump zizmorcore/zizmor-action from 0.5.3 to 0.5.5 in the github-actions group#1665

Merged
wochinge merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-ad4ab43b8a
May 21, 2026
Merged

chore(deps): bump zizmorcore/zizmor-action from 0.5.3 to 0.5.5 in the github-actions group#1665
wochinge merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-ad4ab43b8a

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 21, 2026

Bumps the github-actions group with 1 update: zizmorcore/zizmor-action.

Updates zizmorcore/zizmor-action from 0.5.3 to 0.5.5

Release notes

Sourced from zizmorcore/zizmor-action's releases.

v0.5.5

This is a no-op release.

v0.5.4

  • 1.25.0 is now available via the action
  • 1.25.0 is now the default version of zizmor used by the action
Commits
  • a16621b Bump pins in README (#112)
  • 1c03e04 chore(deps): bump github/codeql-action from 4.35.2 to 4.35.3 in the github-ac...
  • b572f7b Sync zizmor versions (#111)
  • 06928c5 chore(deps): bump github/codeql-action in the github-actions group (#109)
  • 5ea8b96 docs: Update link to GitHub docs (#108)
  • 849ac26 chore(deps): bump the github-actions group with 2 updates (#106)
  • 814f977 Bump pins in README (#103)
  • See full diff in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 1 update: [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action).


Updates `zizmorcore/zizmor-action` from 0.5.3 to 0.5.5
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)
- [Commits](zizmorcore/zizmor-action@b1d7e1f...a16621b)

---
updated-dependencies:
- dependency-name: zizmorcore/zizmor-action
  dependency-version: 0.5.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels May 21, 2026
@dependabot dependabot Bot requested a review from a team as a code owner May 21, 2026 05:57
Copy link
Copy Markdown

@claude claude Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — Dependabot SHA-pinned bump of zizmor-action from v0.5.3 → v0.5.5.

Extended reasoning...

Overview

This PR is a Dependabot-generated dependency bump that updates the zizmorcore/zizmor-action GitHub Action from v0.5.3 to v0.5.5 in .github/workflows/zizmor.yml. The change is a single line updating the SHA pin and version comment. The action remains SHA-pinned (best practice for third-party actions). v0.5.5 is documented as a no-op release; v0.5.4 made zizmor 1.25.0 the default.

Security risks

None of concern. The action is pinned by full commit SHA, mitigating supply-chain risk. The workflow itself has minimal scope (contents: read, permissions: {} at top level) and only runs zizmor static analysis on workflow files.

Level of scrutiny

Very low — this is a mechanical, dependabot-generated bump touching only a CI workflow file. No application code, no production code paths, no logic changes.

Other factors

The PR description includes the upstream release notes confirming the minor version bump is non-breaking. Standard low-risk dependency update.

@wochinge wochinge merged commit e1025bc into main May 21, 2026
19 of 20 checks passed
@wochinge wochinge deleted the dependabot/github_actions/github-actions-ad4ab43b8a branch May 21, 2026 07:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant